How to Balance Security Controls with Operational Freedom
Bill Mackey brings a refreshing perspective to cybersecurity leadership after 25 years in the technology and security space, culminating in his role as Chief Information Security Officer. Unlike many in the field who focus solely on technical controls, Bill emphasizes that effective cybersecurity is fundamentally about protecting people and organizational missions, not just data. His experience spans everything from help desk support to incident response and forensics, giving him unique insight into how cybersecurity stress affects both professionals and the organizations they serve. The alarming statistic that the average CISO tenure is only 18 to 26 months highlights the unsustainable pressure many security leaders face, often juggling responsibilities equivalent to being “a police officer, detective, firefighter, and car mechanic” all at once.
When it comes to outsourcing cybersecurity functions, Bill advocates for a risk-based approach rather than fear-driven decision-making. He emphasizes that organizations can never outsource responsibility—they can only transfer certain tasks while maintaining accountability for outcomes. The key is understanding the difference between risk appetite (what you’re willing to accept) and risk tolerance (what your business can actually survive), much like his analogy of loving ice cream but having low tolerance versus disliking tomatoes but having high tolerance. Smart leaders should demand shared responsibility matrices, incident response plans, and evidence-based reporting from their security providers, while being wary of vendors who use scare tactics or refuse to provide specifics about detected threats.
The ultimate goal is achieving the delicate balance between security and usability—what Bill calls the fundamental dichotomy in cybersecurity. Organizations must navigate between implementing necessary protections and maintaining the operational freedom that enables employees to do meaningful work. This balance varies significantly based on regulatory requirements, company culture, and risk posture, but the most successful approaches focus on strategic risk management rather than simply accumulating security tools. By taking a holistic view that considers both technical controls and organizational culture, leaders can create cybersecurity programs that protect their missions while empowering their people to achieve business objectives.
Episode Summary:
Join Cody Lents from COVI as he sits down with retired Chief Information Security Officer Bill Mackey to discuss the real challenges facing cybersecurity leaders today. With 25 years of experience in technology and security, Bill shares insights on why CISO burnout is at an all-time high, how business leaders can responsibly outsource cybersecurity functions, and the critical balance between protection and productivity.
Key Topics:
-
Why the average CISO tenure is only 18-26 months
-
The difference between risk appetite vs. risk tolerance
-
Red flags to watch for when evaluating security vendors
-
How to avoid fear-mongering in cybersecurity decisions
-
Balancing security controls with employee empowerment
-
Essential questions to ask your managed security provider
Connect with COVI:
Instagram | Facebook | Website | FREE IT Strategy Analysis
Links to The COVI Way Podcast
YouTube | Apple Podcasts | Spotify
Episode Transcript
The COVI Way - Episode 9
Featuring Cody Lents and Bill Mackey
Cody: Welcome to The COVI Way, the podcast where we break down the intersection of people and technology because it isn’t just about fixing problems. It’s about enabling people to do their best work. I’m Cody Lents, the VP of sales at COVI. And today we’ll attempt to identify key information leaders need to successfully understand and address cyber risks with Bill Mackey, chief information security officer with two decades of experience combating threats and establishing safe company cultures.
Thanks for joining us today. Today we have Bill Mackey. He recently retired Chief Information Security Officer. Don’t worry, he’s not here to scare us as we dive into the realms of cybersecurity. We’re gonna look at more of what is good and appropriate in that space as opposed to scary and ambiguous. Bill has an often unique perspective where it’s not just about protecting data and it’s also about protecting people and the mission of an organization. So Bill, would you mind giving us a little bit of your CISO journey as an information security officer?
Bill: Yeah, sure. I’ve been in the technology and security space now for 25-ish years, give or take. And in that journey, I’ve done everything from help desk and culminating in that chief information security officer role. And that includes forensics, incident response, just day-to-day admin, engineering, all kinds of things. And so I’ve had this wide depth and breadth of work-related skills and experiences that now I can look back and see some trends and some things that ultimately led to my decision to walk away, so to speak. And just because of that burnout experience and that more and more individuals are seeming to have, I saw a statistic a while back and I wish I could remember who said it, but it was the average tenure of a CISO is about 18 to 26 months.
Cody: Oh wow. Not long. It’s a lot shorter than I thought. I was having like more of like a seven to eight year mark in my head.
Bill: And well, this is just the CISO role itself. Good point. When I first got into security, I was told by one of my mentors and one of the quote unquote living legends of the day that the average tenure of a security professional is eight years. That’s extended now because it’s becoming more mature, more roles, but there is still that burnout that can happen just depending on a lot of factors and nuances, which we’ll probably get into a little later.
Cody: Yeah, no, that’s one of the, my first question for you today was gonna be like most people don’t know, but I believe that the average tenure of a security professional is less than an air traffic controller or the rate of stress is higher than air traffic controller or some axiom like that that I heard not too long ago. When I heard that you were retiring, I wanted to make sure to ask you about that. What is this high stress level burnout of cybersecurity professionals?
Bill: Yeah. So like I said, there’s a lot of possibility, a lot of nuance to it. I was having a conversation a few days ago about the specifics and the way that I put it, it’s kind of like, you know, if you had this Indianapolis, the city of Indianapolis, and you’re like, you know what? We have a little bit of crime creeping in and we need to keep that at bay. So let’s hire a police officer. Just one, maybe two, you know, as you grow. To take care of all the crime and oh, by the way, we’ve noticed that we’ve had some increases in fire. So we’ll just have the police officers do it. Right. And, oh, and by the way, the police cars, the squad cars and the fire engines need some maintenance. So police officers can take care of it. And it just builds and builds in that regard where there’s just more and more happening.
Plus you never know, so you may schedule that maintenance, right, for the squad cars, but then all of a sudden there’s a crime and you have to take off. So you, okay, what do you do? You know, you gotta go take care of the emergency, put the maintenance on hold, and then you gotta try and get back to it. But then in the meantime, other things build. So they are a police officer and a detective and a firefighter and a car mechanic. And then they’re trying to sprint over to the bank robbery, but the wheels are falling off the car because they couldn’t get to the maintenance to tighten the lug nuts. So, or at least they have the stress that the wheels might fall off the car. So, and I do want to mention, I’m not trying to compare the role with police officers or fire. Right. Those are such vital roles. But we don’t want, I don’t want to make it sound like the threat level or anything like that is the same. Although could in terms of things like healthcare, right? Where a data breach could be life or death.
Cody: Oh, yeah, that’s a good point. In that same line of thinking, if I’m driving a car on 465 around Indianapolis and my car is a 2025 Kia Sorento and I can drive 80, 90, 100 miles per hour and feel really comfortable. But if I’m worried about my wheels rolling off because I haven’t done maintenance, I’m pretty uncomfortable at 60. And so or, you feel that misalignment or imbalance in your wheels and you’re uncomfortable because your hands are shaking so much on the steering wheel. So in the cybersecurity space with that type of stress level, how does that impact the risk exposure of the organizations that you’re serving or that you’re a part of?
Bill: Yeah. And this is something that’s near and dear to my heart because I’ve seen it in a lot of different capacities. But what can happen is one. The first thing that typically goes is because you’re constantly moving, you’re constantly in firefight mode or whatever. Typically, you forget about self-care, de-stressing, the sleep. Sleep is important, right? Especially during an incident, you may be up 24, 36 hours working on an incident, get a few hours of sleep, do it again. Well, what does that do?
Well, then you start getting tunnel vision. You start going down the wrong path. You forget about other things. Again, self-perpetuating. You forget more about self-care. You forget about your family, friendships, whatever it is. And so then you start getting the mental decline on that aspect. On the other side, business-related, you get that tunnel vision. You may forget to communicate. Well now we have a bunch of data breach notification laws in the United States as well as throughout the world. And you have a certain amount of time to report. Well, if you’re investigating that, you forget to communicate, you may miss that, now you have fines. Not only that, but you may have lawsuits that come, you may have all kinds of other things. You may also miss. Or even communicate, if you’re on a team, like communicating vital information to another role on…
Cody: Absolutely. That’s why I chuckled, because I think of when I’ve been under stress and communicated very poorly to my cohorts here at COVI. Absolutely. Do you have any examples of something that you experienced on one of your teams in the past where you could contribute stress or overcapacity as a trigger to an elevation of severity in a cybersecurity situation?
Bill: Yeah, there’s the one that comes to mind and it was a bigger organization. But what happened was they had a breach. I was called in for incident command, which is the person that oversees it coordinates the effort. I had about, I don’t know, probably about 20 guys that were working with me on cleaning this up. And before they actually brought me in, they had somebody else that was taking care of the situation.
He was stressed, he was tired. And so after about a week, they weren’t getting anywhere. So they’re like, hey, we need to fly you out. We need you to come in and help us with this. Okay, cool. So I get out to DC, go immediately from the airport straight to the organization. And I said, okay, I go through my normal steps of getting the facts versus opinion and things like that. And I said, okay.
So we have this, do we have any avenues of how this may have happened? And they’re like, no. And I was like, okay, well, let’s start at the basic. They got in somehow, let’s look at the firewall. And so we looked at the firewall and we were going through, I mean, literally line by line of all the entries in it. I was asking questions, hey, what’s this, what’s this? And then I said, okay.
Skipping down now, what’s that doing there? And what they had was a, what’s called a permit any, any rule, meaning anything from the outside could get internal if there’s certain conditions in place. And they’re like, Oh, we don’t know. And I said, well, why don’t we know and get it out of there? I don’t care if it breaks things because at this point in time it’s causing us problems. So they ripped that out and what it was was they were all just so tired and they didn’t have, you know, they were each in their own silos. They were focusing in their areas that they weren’t collaborating, going back to the communication. They were all tired. The guy that I was working with that was doing the incident command before I came in, he hadn’t left work or seen his family in, I don’t know, like two or three days. And I finally, after that, I was like, dude, just go home.
I want you to take the, you go home, spend some time with your wife and kids, go to bed and then come back about 10 or 11 the next day. Just take some time off. And with that, while the other guys were there, they were a little bit fresher. We were able to get everything cleaned up, not cleaned up, but sealed off so that the access was terminated and we had control of the situation within 36 hours. This is a fairly large organization. So I feel good about that, especially after it’s been over a week that the attacker had access.
Cody: So just for clarity, I apologize to anyone who’s lost track. This is my geek out mode here and the cybersecurity piece is what I went to school for. When you got there and you were going through the firewall rules, which are just configuration elements that allow access or deny access to the organization’s network. When you got there, was there an active incident that was still active, like ongoing, or had it stopped and they were just doing like cleanup and forensic and recovery?
Bill: All the above. So there was an active attack still going on. But the interesting thing is the attackers didn’t know the entity that they had breached. It’s probably an external scan that found their entry and they didn’t have a plan. And so when they got in, they, they didn’t, they weren’t trying to expand their footprint or anything and get confidential information. They turned it around and were providing scams elsewhere. And so there was financial fraud that went on that we were able to detect and find and things like that. But, but they didn’t dive any deeper into the rest of. So there’s a little bit of luck on that one.
Cody: And so in light of that particular experience and the ones like it, but also just your overall experience as a cybersecurity leader, what should a non-technical leader of an organization like a CEO or a business owner or even just maybe it’s an IT director that is just older and hasn’t got the last decade of, you know, actually getting his hands dirty into the space of cybersecurity. What should they be thinking about to responsibly outsource some cybersecurity functions or maybe all of the cybersecurity situation with like a managed security services provider or something along those lines?
Bill: First and foremost on that, my advice is, and again, we’ll talk about it a little bit more later, but more than likely is that you can never outsource responsibility. So what happens a lot of time is, we’re transferring this risk to our MSP or MSSP, but ultimately the business is still responsible for anything that happens. You can’t abdicate that responsibility.
We also talk about the fact that there’s, have this term called risk appetite. We also have the term risk tolerance. And a lot of people try to equate those, but there is a subtle difference. And the way that I like to describe it is with first tomatoes. I don’t like tomatoes. My body however, has a very high tolerance for tomatoes. I can use them, can use the nutrients from them. Really good for my body. My appetite, not so great. I have a very low appetite for tomatoes. On the other hand is ice cream. I have a great, huge appetite for ice cream, but my tolerance level, my body’s tolerance level is low. It starts causing issues, right? And so we have the same concept of with information security as risk tolerance versus risk appetite and trying to equate or trying to get those in balance.
Cody: How does that relate? Like your analogy makes perfect sense to me. But how does that relate to a cybersecurity situation or maybe a leadership’s analysis of a cybersecurity situation?
Bill: Yeah. So let’s talk about, you know, an entrepreneur. They just started. I mean, they have this business. They’re in growth mode. Right. Revenue can be tight because they’re growing, they’re adding new employees, whatever it is, right? But obviously that entrepreneur has a very big risk appetite. They started a business, they went out and started something new that could actually fail. And so they typically have more of a risk appetite. But the business itself doesn’t have a whole lot of money. You know, because they’re growing, you know, the margins are tighter for whatever reason. Whether it’s they haven’t systematized things, they haven’t, they add again, new employees to help with the workload, whatever it is. So if the CEO, the entrepreneur says, yes, we have this great big risk appetite, we can take on more risk. But then one of those fails and it costs the business, you $20 million, but they’re only bringing in $10 million. That could be pretty detrimental to the organization.
Cody: That makes a lot of sense. Like it’s basically like, oh, well, my tolerance is what I can actually survive with. And my appetite is what I’m okay dealing with. Yeah. Like emotionally or capacity or whatever. So when you’re working with or if you were advising or just for our audience today, someone who’s leading an organization like that entrepreneur or maybe it’s a larger, more mature organization, what do they need to be? What information do they need to know? Like, oh, this is a good thing to outsource and this is a good provider to outsource to. Like, what does good mean when you’re thinking about outsourcing cybersecurity?
Bill: So. That’s a very nuanced question with very nuanced answers, obviously. Good needs to be defined for that organization. Why are you wanting to do it? That’s the big overarching question. Why do you want to outsource? So that’s where your appetite and threshold come into play is like that helps you define what good means. It’s definitely part of it. Then, you know, are we growing and we just and we need extra capacity.
Okay, cool. That’s a great reason to outsource. Well, what do we need to outsource? Well, again, I mentioned that you can’t abdicate the responsibility. So you’re still responsible for everything that happens. If you’re going to look for, whether it’s an IT provider or a security provider or both, is that are they fitting in with your culture, your cybersecurity culture, are they backing you up? Are they providing you evidence that what they’re doing is the right thing that they are, especially in terms of cybersecurity, if they’re doing alerting and monitoring, are they providing you with the reports? Are they providing you, we’ve caught this anomaly, we checked into it. And we think there’s more to it, or are they just trying to get it done, especially if it’s something maybe they didn’t follow a change control procedure or something like that, and now they don’t wanna lose a business. So are they communicating, are they providing the evidence that they’re following through with what they say they’re going to do?
Cody: Yeah, so you’re kind of listing a few things off there. It sounded like it was almost like these are the non-negotiables, evidence being one of them. What would be like a bullet list of non-negotiables from outsourcing specific to cybersecurity? I know that this show, we talk about a lot of different things. And from an outsourcing perspective, there’s lots of IT you can outsource. But if we just keep it focused on cybersecurity for the non-negotiable list.
Bill: Non-negotiables. Again, that’s going to be dependent upon the situation who, but for me, it’s one thing that I require is a shared responsibility matrix. I want to know as a CSO who’s responsible for what. Cause it’s easy to say, yeah, yeah, we do X, Y, Z. You know, we do the monitoring and alerting. We set that up. Cool. But then I don’t get any alerts. I don’t know what’s going on.
Well, no, we just set it up. We didn’t agree that we were going to actually tell you. Analyze it. And that’s a very, probably not ever gonna happen, but it gets the point across, right? I want to know as specifically as possible who’s responsible for what. And that way there’s no question. Do they also have, that’s one. Number two is do they have incident response plans in place. So you going back to, know, they did something, are they following up with it? Are they investigating? Are they communicating? What does that look like? What are the SLO, SLA, SLOs that they’re going to use in order to communicate? Get in touch with me. What’s the threshold, right?
Cody: That’s service level agreement or objective, right?
Bill: Correct. Correct. That’s number two. Are they willing to be audited? It’s easy to say, yes, we are secure. Yes, we are doing this. But how do I know? You know, I believe it was Ronald Reagan, please correct me if I’m wrong, but he said, trust but verify. And it’s like, I want to trust you, but at the end of the day, I’m still responsible. So I need to make sure you’re doing what, what I need you to do.
And it doesn’t have to be you go in and you review their policies and procedures and audit them. It could be something like a SOC 2 audit. If you’re in the defense industry, could be the upcoming CMMC certification. It could be that ramp certifications. could be ISO. So like a third party audit. Yeah, third party that Just depending on what’s relevant to the organization or you.
Cody: Yeah. I’m sure there’s more than one, but like what’s one, an example of one thing that a lot of organizations would think that they’re like, oh yeah, we’re covered, we’re protected, but then find out they’re not.
Bill: One thing, I would say the auditing. And that is a very broad category, but in specifics, if we’re talking the technical aspects, so many think that their auditing level is where they need it to be to be able to detect incidents or be able to do forensics and they’re not. So the one example that I always bring up with that and it’s amazing how many shops still can’t tell me whether or not they do this or not and then they find out they’re not. Will log failed login attempts cool. We now know that we’re having a brute force attack. But then they stop. Did it stop because they got in or because they gave up? So we have to know the successful logins. Because if I’m looking at this and I see just hundreds or thousands of login attempts and then all of sudden they stop, I have no idea why.
Cody: Yeah, that makes sense. So you’re saying some people would only be auditing the fails and not successes. As someone who’s like an operations leader of an organization or something in that vein and they’ve outsourced IT. What is something that you would recommend that they ask for evidence to go back to what you said before, ask for evidence of their protection on? Like what’s a version of that? There would be something that’s be simple for them to digest and understand.
Bill: Are you wanting something from more of a leadership position or like if you had like a technical person that was-
Cody: Like a general leader.
Bill: General Without the technical knowledge, yeah. Okay. First, as part of the process of selecting the vendor, I want to know, can they speak in my language? Right. Just like there’s all these different languages around the world, you know, and I can’t, I can’t understand French very well. Like I can pick out a few words, but I have no idea if two people are having a conversation in French. Same thing with tech speak, right? Lots of jargon, lots of nerd speak, so to, you know. And-
Cody: Tribal knowledge.
Bill: Yeah. And so if I get a report and it’s like, here’s all the alerts that we got that were, you know, malicious or whatever, doesn’t mean squat to me. You could just be blowing smoke up, you know, up my rear end. But what I want to know is how many did you detect? How many were real, you know, and how many did we get? You know, came to us that we’re actually a problem. And the thing is, is the detection, most people are like, well, I want, and this is great for business people to know, they always want to know, want that, how many detections they want that number to decrease. I never want it to decrease because I don’t know if it decreases, are we catching anything? If it went to zero, my first would be, what did we miss? We’ll never know if we have that.
Cody: Good perspective. It’s kind of like the opposite of gamification. It’s like you want to see that score go up and up and up. And when you’re playing a game, but you would think in cybersecurity, you want to see those detections go down and down and down. But you really want to see them stay stable. Is that what you’re saying?
Bill: A stable fluctuation, you know, a little bit, but never like dropped completely down because the next number right is how many were actual events or incidents that we had to look into. Well, if you’re getting, you know, a hundred thousand hits, you don’t, you’re not going to be investigating all of them. Right. Hopefully. Yeah. And obviously this gets into things like having a SIEM or a SOAR, different tools to be able to, take all that data in and analyze it and qualify it and, and only spit out those things that are most likely issues. But we still should be able to know what are we detecting? And what the problems are. Yeah. If they’re worrying.
Cody: So similar to my last question, and this is a pet peeve of mine, so I’ll try to taper my passion. But cyber security, like I started to being the segment. We’re not here to scare you today. Cyber security, when you hear about it in the news, just like with most headlines, it’s human nature. We’ll get more clicks if we go negative. Same thing with like cybersecurity, whether it’s a solution that’s marketing or outsourcing, that’s marketing, whatever it is, it’s, oh my goodness, the world’s on fire. Not that inaccurate from a cybersecurity perspective, but you’re about to burn down, probably inaccurate. And you have to have this thing to survive. And so that fear mongering approach to marketing especially, but I’m sure in like sales or qualification conversations, that’s probably still the undertone of that.
What or how would you advise someone like Dave of COVI to evaluate what a genuine risk is versus what is just, you know, fear and a marketing ploy?
Bill: So what I would say there is from a very detailed tactical perspective, if they’re just coming at you saying you’re going down in flames if you don’t do this, it’s a red flag to me first and foremost. So you can weed out a lot there. You know, an example I had there, had a client once and this will date me a bit, but the back when peer to peer networks were a big thing. And for those that may not know what that is, is that it would be these just different computers out on the internet that connect to the network and they would have certain data and you could pull it from them. And so that, so data.
Cody: Like a it’s like a big open.
Bill: Yeah, exactly. Like big open internet sort of thing where you don’t have any of the security involved. Correct. And a host could pop on, pop off, you know. So if this server had data on it and then it went offline, nobody, if it wasn’t somewhere else, that data was no longer available. So people would share, you know, all kinds of things, pirated software, music, movies, personal information, all kinds of things through this.
And this client of mine, had a company reach out to them and they said, we found your data on a peer to peer network. And it freaked the company out, obviously, because I want to say they were a health care organization. So kind of bad if health care data gets out. The only way you can fix it is to buy our product. And so here’s what I want you to do.
Tell them you want the data. You want to know what data it was. Their response was, the companies, not my clients, their response was, that’s our proprietary information. So no, no, no, no. If it’s my data, I have a right to know where it is. If you found it, I want to know what it is because I have to report this. Or possibly have to report it. I also have to figure out what’s going on and how to fix it and whether or not your solution is the right solution or not.
And they wouldn’t do that. But the company was still freaked out that they actually paid us to once a quarter just search peer-to-peer sites for their data.
Cody: Did you ever find anything?
Bill: Never found anything. So it’s almost like a black market version of fear mongering there. Exactly. And what I told and advised the client was more than likely there was some data there, but it was probably like an email address or two. Technically, that’s their data, right? But we’re not so concerned about that, right? Because we use email addresses everywhere. So who really cares? What I’m concerned about was confidential information. If they’re not willing to tell me that, then I can’t even trust them as a vendor.
Cody: Yep. That makes sense. So you were able to use almost like a strategic questioning strategy to qualify the severity or even reality of the situation.
Bill: Yeah. And then to go a little bit deeper on your question, from a strategic point of view, always advocate for… So what happens a lot of time is we talk about cybersecurity. I’m not a big fan of that term. I’m old school, so I still use information security because I want to secure the information regardless of the media that it’s on, whether that’s a hard drive, a flash drive or in somebody’s head. I want to protect the information. That’s what’s typically valuable. Then we have cybersecurity, which kind of says, okay, this is the stuff, you know, the computers and internet and protecting that aspect. Then we have IT security, which is typically just, you know, the local stuff, the servers, the hard wire or the actual wires, the switches, routers, et cetera. So anyway.
Went off on a rant there. But I use cybersecurity just because that’s what everybody uses. But it’s also misleading because we say it’s security. So we’re protecting something. Well, I always say, well, why are we protecting it? Right? We’re more concerned about the risk. So I advocate for a risk-based perspective rather than trying to secure something. Because if I’m securing it, great, I can secure it by just not having the data, right? I can have a secure company just by not having the company. Is that the best way to do it? Well, obviously not. So I have to look at the risk and evaluate is this a high risk situation or a low risk situation and do I want to mitigate it? And so when somebody comes to me and says you need to buy this product, well, that’s a point solution that fixes one problem. Well, if I have a risk based mentality, and I say, Oh, here’s you know, our risk, whatever those are. And I keep track of typically what’s called a risk register, keep track of that. And then how am I going to mitigate, delete, or remove transfer, whatever, those risks. And if I’m going to mitigate it or manage it, how am I doing that? Well, I’m using this tool, this tool, this tool, this tool. Those four tools can also be used for this risk, this risk, this risk.
Oh, and now this guy came to me and tried to sell me his tool and it does this, but we have alerting and monitoring, we have DLP, we have these other tools that will also solve that. I don’t need another tool. Now you can actually start using multiple tools for multiple risks instead of using point solutions. It’s moving down that maturity matrix or that maturity level from, you know, we just put things in place because we think we need them or we do need them to actually have a strategy.
Cody: That’s one of the things I was thinking of. I know you said you were shifting gears to the perspective of risk versus just cybersecurity, which is like a lot of times I call it risk management or technical risk management. There’s a, talked about risk appetite early on and you talk about risk threshold early on. And a lot of times when you put all those components and a couple other components together, you establish what a lot of people call the risk posture, is where you can correct me if I’m wrong, but that’s where you’ve got your executive summary of your risk situation so that you can start to make strategic decisions around it, just to simplify it. A little oversimplified, but simplify it.
I know, and I know it’s really important to you, and it’s vitally important from mine and COVI’s philosophical perspective, that we should not only be looking at that posture of risk, but we should also be looking at our culture of risk in cybersecurity in an organization. Because if you can put the technical controls in place to make your risk posture amazing, but then you’re more likely than not, production goes way down. Engagement and quality of work life goes down. So that balancing act, you balance the scales or that tightrope that you walk between restriction and empowerment. Can you talk a little bit to that point and what organizations face and ways that they can kind of find that good balance, strike that golden tone of, OK, we are in a good place from a risk posture perspective, but our workforce or our leadership team or our creative thinkers or whatever the version is are also empowered to do the meaningful work that produces the output that we want to generate for our customer experience.
Bill: Yeah. And so we have this dichotomy in cybersecurity and most people have probably heard it. Usability versus security. If security gets tighter, usability goes down. If we loosen security, usability goes up. But you also have less security. So, unless restrictions, it’s easier to do things, right? And so, it’s also then, so we have to balance as you said, but it goes to, again, culture, goes to risk appetite, risk tolerance, those types of ideas. Because for instance, you know, somebody, does a covered entity in HIPAA language, do they have to be compliant with HIPAA? Yeah, right.
Cody: Can you tell us what a covered entity is real quick?
Bill: So a covered entity is anybody basically, I don’t have off the top of my head the categories anymore, but it’s anybody that has to be compliant with HIPAA or needs to be compliant with HIPAA. I say it needs to be compliant with HIPAA only because you don’t have to be. Right. I don’t say that to say, don’t do it. But you can take the risk. Going back to the risk-based model, you can take the risk that you’ll never be found out. Well, now it’s either ever found out, heavy fines from the federal government, penalties, possibly imprisonment, constant audits, constant audits, all kinds of things that can happen. So as a risk advisor, I would say yes, you want to be compliant with it, but you don’t have to. Does that carry with a certain security controls? Yes. Does that mean that usability may go down? Yes. So what’s that balance that you’re willing to hit? If you’re not under certain compliance initiatives or regulations, you have more freedom there.
Cody: Yeah, less risk.
Bill: Yeah, less risk. Which is why those regulations exist to begin with. Correct. And so you can, you can play with that a bit. Some, would just say wholesale, everybody should do them, right? Use complex passwords, use multifactor authentication, have some sort of endpoint detection and response, those type things, because you have basic hygiene. It’s going to take care of the majority of your problems, especially if you’re smaller. But to the degree of what products or how many products or that, it all depends on that culture.
Cody: And products like cybersecurity tools.
Bill: Yeah, correct. So let’s just take a multifactor authentication, for example. How do you do that? Well, there’s how many companies out there, vendors that offer this. And do you do soft tokens on your cell phones? Do you do text messages? Do you do soft applications, do you do a hardware token? What do you do? Well, that all depends. That to say there’s a lot of options. There’s a lot of options. And so your culture is going to play into that. Do you offer multiple, you know, maybe, maybe not. If you’re less prone to or if you’re if you have less of a risk appetite, you may say we’re using hardware tokens because they’re gonna be one of the hardest ones to break and blah, et cetera, et cetera. So everybody has to do that. Well, now everybody has to carry this hardware token around and learn how to use it and things like that. So it’s disruptive from a learning curve perspective. What if you live at home? And then others, if you have your phone, everybody knows how to get a text message, right? So it’s like, I get a text message. Well, now you have to think about, are we willing to possibly have SIM swap attacks go on, is somebody hijacking your phone.
Cody: Yep. So does that answer your question? It did. I think that can you I’m going to ask you for two examples. First one is can you provide me an example of when you’ve found that cybersecurity has been overcomplicated or over engineered to a point that has been too disruptive and restrictive to operations. And I’m going to ask you the reverse of that question next.
Bill: OK. Yes. That scenario plays out in a lot of ways. Typically, what happens that I’ve noticed is companies as they grow. IT shops are already stretched thin. Not a whole lot of money or whatever. And so they just bolt on solutions. Well, when you don’t have a strategy around your IT operations and you just bolt things on, now you have possible gaps in security and things like that. So then your monitoring gets in the way. So let’s look at it this way, right? If you’re going down the highway and there’s no exits. Smooth sailing, right? It’s easy. You know what you’re doing. And if you need to count cars, it’s easy, right? You can just be like, okay, they’re coming at me. One, two, three, four, five. And you can get an accurate number. Now what happens if we have exits and roundabouts and multiple roads coming in and you need to know how many cars are actually on that highway at any given time. Well, one car may get on and get off before they come to you. So you have to have multiple places that you’re monitoring to count as cars and count them. You also have to have, what if somebody gets on and gets immediately back off? Does that count? And how do you catch it and account for it? Exactly.
You can start seeing if you have bolt-on solutions, you now have multiple entry points of attacks or disparate systems that can’t communicate with each other to share data, to share audit logs, whatever it is. And so now you start building up this real complex scenario. What typically happens then is that it’s forgotten. One system may be forgotten or everything because there’s just too much to look at. We just give up. Then bad things happen, right? Attackers get in, nobody knows. It could be, you know, a system breaks and we don’t know how to get it back up because there’s no documentation or it was piecemealed together and it’s just kludgy and fragile. So, do you…
Cody: Earlier example of the explicit allow rule that you found in that fire that you’ve flown out to fight. Was that a result of over complication of tuning rules or the opposite a result of oversimplification and by putting that rule in place?
Bill: That’s an interesting scenario in that. So what happened there was it was a junior network engineer that put that rule in. He was doing some testing and he was less than, I think less than a year out of college at this point in time. Didn’t know any difference. And I’m glad I was there and please don’t take this as patting myself on the back, but I was able to save his job because the immediate response was, you’re responsible, we’re firing you.
And I said, well, we can’t do that. It’s like, well, he did something he shouldn’t have. I said, how did he know? He’s a junior, less than a year or whatever it was out of college. Did you train him? Tell him that you don’t do that? Do you have SOPs and policy saying don’t do that? Do you have change control in place that says, hey, for any changes to production systems, we’re going to, have to know about. You have automated monitoring and alerting set in place so that when he made the change, it kicked off an alert saying, Hey, somebody made a change. You know, all these different things and went through several of them like that. And they realized, Oh, we’re actually to blame because we don’t have these things in place. Yeah. Program and safeguards. Yeah. So that was a little bit different of a scenario in that they were lacking a lot of the basic tenants of a good solid information security, cybersecurity program. Now that being said, was their environment partially to blame? If the attackers would have penetrated further into the network, then yes, they had such a convoluted network that it…
I’m reticent to say this, but I’m hesitant to say it, you should say, but I’ll just put it this way. It would have been easier for them just to scrap everything and start building from scratch. So that’s the cybersecurity operations impact of it. How did that impact, and I’m just going use the same example since we’re there, how did that impact that organization’s normal operations, like production and meetings and whatever they did to create the widget to get out the door?
Yeah, it actually took the entire IT team plus multiple, gosh, it was probably six or eight at a minimum from the parent company that came in. That not only affected this company, but the parent as well. What about the non-technical workers? What was their experience? In that regard, it wasn’t so much any of the employees themselves of the company, it was their clients.
Cody: Yeah, so they housed some applications for clients and it took those off. So there it’d be like if Netflix just stopped working and we’re all asking for our monthly payment back because we missed our time to watch our shows or if the the parking system wasn’t working. So like now we can’t charge parking tickets for the for the municipality and our software solution went down. Yeah. And so what the on what the ramifications were downstream, I couldn’t tell you, but I can tell you by the nature of the services, it was probably pretty significant. That’s crazy. Well, we’re at time. So I’m going to wrap up with with.
Before we do the tech tip, I have one thing. If you could just provide like if you got the ear of some senior level executive at a Fortune 500 company or whatever, and you were able to write down like one sentence on a memo for them because you heard that they were going to try to outsource IT, what would that one sentence be?
Bill: I’ve said it probably a couple of times. You cannot abdicate responsibility. You have the responsibility to have that, to manage the risk of the organization and that includes that of IT, of the information, et cetera. So you cannot abdicate that. You can’t outsource the responsibility.
Cody: So terms and conditions between partnerships and providers does not cover that responsibility?
Bill: In certain aspects, there will be. But at the end of the day, you know, if, you know, company XYZ gets breached and their client data gets, you know, leaked out on the internet, whatever social security numbers, et cetera, it’s not going to be the IT provider, the MSP, they may get sued, but it’s going to be the company at the end of the day that’s going to be held responsible to the point they may lose. They now may lose reputation, revenue, any number of things. So it’s like if in the old school hacking days, if a vendor, if someone hacked a vendor’s laptop, like an HVAC company vendors laptop and that HVAC company had access to that corporate network, then though the fault was with that HVAC company, the responsibility and all of the media and the PR and the penalties and the fees, they land on the organization, even though they likely sued for some of that back. They still had to deal with the entire fallout on their own.
Cody: Absolutely. And that’s a scenario, actually. However long ago it was, 10 years ago, 15 years ago now, Target was…
Bill: That’s what I was talking about. That’s funny. Does anybody even know the name of the HVAC company? That was the actual cause. That’s a good point.
Cody: So then I’m going to let you do the tech tip for our day. So if you could just talk to them in the camera and do a quick tech tip. We just usually do a quick tech tip to round out this segment.
Bill: Sure. As a business and as a business leader, with that theme of you can’t outsource the responsibility, you can’t abdicate your responsibility of information security, and with more going to outsource entities such as MSPs, MSSPs. You need to be able to audit and verify those entities. We talked about that earlier, but it’s very crucial. More and more, you’re going to that, or companies are going to that. And one of the big parts of it is we didn’t get to, but you have, for example, vendor lock-in. If your data is someplace, is the company making it hard for you to get your data back so you can move someplace else?
You know, are they actually securing your data? How can you verify that? Are they telling you if they had a breach so that you can participate in incident response? Who’s responsible for what? So that’s my biggest tip. Yes, the, you know, the typical password hygiene and all those important, but as you move away from internal resources to partnerships, make sure that you can verify what they say they’re doing, that they’re doing it, and that you actually have a good partnership. That’s what I always appreciated about COVI, because they actually provide a lot of service, great services, but they also provide extra on top of that. Here’s what we’re doing. Here’s where your value is, those type of things.
Cody: To do that, if I’m looking, if I’m COVI and I’m not an IT company anymore, I’m just doing what I’m doing, if I’m looking to outsource, what’s that question I ask for that audit? Like, hey, how do you handle an audit? Or hey, what evidence would you give me if I asked, what are you doing? What question do you ask there?
Bill: The first question I would ask is, do you have any sort of third party attestation or assessment? And there’s all kinds of them out there, depending on where, what space you play in. Like I mentioned earlier, it could be CMMC, it could be FedRAMP, it could be HIPAA, PCI, all those different things.
Cody: What’s a good general one that’s not compliance specific?
Bill: So if you actually want a certification like ISO, that’d be a good way to go. Not a lot of companies are gonna do that, but if you go with some of the bigger companies, they’re most likely gonna be looking to SOC 2. It’s good. I don’t want to downplay it, but you have to be you have to actually look at the report. You can’t just take it. Take it. Yeah, because, well, there’s I won’t get into the specifics of that, but I’ve seen some pretty poor SOC 2 audits. And so you need to actually review that. But it can be a good source.
Cody: I like it. Well, thanks, Bill.
Bill: Yeah, absolutely. It’s been fun.